Repository navigation
Expand file tree
/
Copy pathMODULE.bazel
More file actions
432 lines (383 loc) · 15.2 KB
/
Copy pathMODULE.bazel
File metadata and controls
432 lines (383 loc) · 15.2 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
"""Bazel Module for WebAssembly Component Model Rules"""
module(
name = "rules_wasm_component",
version = "1.0.0",
compatibility_level = 1,
)
# Dependencies for WebAssembly tooling
# rules_rust 0.70.0 includes the .rmeta sysroot fix (#3860) and the rustc_lib
# filegroup fix (#3727) that fix Windows LNK1181 errors — these previously
# required a git_override pinned to commit 6281d27 (now an ancestor of 0.70.0).
bazel_dep(name = "rules_rust", version = "0.70.0")
bazel_dep(name = "bazel_skylib", version = "1.9.0")
bazel_dep(name = "platforms", version = "1.0.0")
bazel_dep(name = "rules_cc", version = "0.2.17")
bazel_dep(name = "rules_go", version = "0.60.0")
# OCI image signing capabilities
bazel_dep(name = "rules_oci", version = "2.3.0")
# aspect_bazel_lib 3.x not in BCR yet — keep at 2.22.5
bazel_dep(name = "aspect_bazel_lib", version = "2.22.5")
# Hermetic toolchain management with pre-built binaries
# Development dependencies
bazel_dep(name = "buildifier_prebuilt", version = "8.5.1", dev_dependency = True)
bazel_dep(name = "stardoc", version = "0.8.1", dev_dependency = True)
# Fix abseil-cpp/protobuf compatibility: protobuf 29.0 expects removed absl/utility:if_constexpr
# Upgrade to protobuf 33.0 which is compatible with abseil-cpp 20250814.0
single_version_override(
module_name = "protobuf",
version = "33.0",
)
# Test dependencies for cross-package C++ header examples
bazel_dep(name = "fmt", version = "11.0.2")
bazel_dep(name = "nlohmann_json", version = "3.11.3")
# Real-world C++ library examples for comprehensive testing
bazel_dep(name = "abseil-cpp", version = "20250814.0")
# bazel_dep(name = "catch2", version = "3.8.1") # Not available in current build setup
bazel_dep(name = "spdlog", version = "1.12.0")
# Note: SSH key generation now uses hermetic WebAssembly component (tools/ssh_keygen)
# Rust toolchain setup
rust = use_extension("@rules_rust//rust:extensions.bzl", "rust")
rust.toolchain(
edition = "2021",
extra_target_triples = [
"wasm32-unknown-unknown",
"wasm32-wasip1",
"wasm32-wasip2", # Now supported with patched rules_rust
# Host targets for cross-compilation in tools-builder
"x86_64-unknown-linux-gnu",
"aarch64-unknown-linux-gnu",
"x86_64-apple-darwin",
"aarch64-apple-darwin",
"x86_64-pc-windows-msvc",
],
versions = ["1.91.1"],
)
use_repo(rust, "rust_toolchains")
# Register toolchains
register_toolchains("@rust_toolchains//:all")
# Go toolchain setup
go_sdk = use_extension("@rules_go//go:extensions.bzl", "go_sdk")
go_sdk.download(version = "1.25.2")
use_repo(go_sdk, "go_toolchains")
register_toolchains("@go_toolchains//:all")
# WASI WIT interface definitions
wasi_wit_ext = use_extension("//wasm:extensions.bzl", "wasi_wit")
wasi_wit_ext.init(include_p3 = True)
use_repo(
wasi_wit_ext,
# WASI 0.2.3 (default)
"wasi_cli",
"wasi_clocks",
"wasi_filesystem",
"wasi_http",
"wasi_io",
"wasi_p3",
"wasi_random",
"wasi_sockets",
# WASI 0.2.0
"wasi_cli_v020",
"wasi_clocks_v020",
"wasi_filesystem_v020",
"wasi_io_v020",
"wasi_random_v020",
"wasi_sockets_v020",
# WASI 0.2.6 (used by wasi-sdk 29)
"wasi_cli_v026",
"wasi_clocks_v026",
"wasi_filesystem_v026",
"wasi_http_v026",
"wasi_io_v026",
"wasi_random_v026",
"wasi_sockets_v026",
# WASI 0.2.8
"wasi_cli_v028",
"wasi_clocks_v028",
"wasi_filesystem_v028",
"wasi_http_v028",
"wasi_io_v028",
"wasi_random_v028",
"wasi_sockets_v028",
# WASI NN
"wasi_nn",
"wasi_nn_v0_2_0_rc_2024_06_25",
"wasi_nn_v0_2_0_rc_2024_08_19",
)
# WebAssembly toolchains. On linux/macos, wasm-tools/wac/wit-bindgen-wrpc
# come from varve instead (see varve.configure(name = "varve_wasm_tools")
# below) — this extension supplies wit-bindgen (plain), wrpc (plain), and
# wasmsign2 always (not in the pulseengine-wasm realm), plus the FULL
# old-download wasm_tools/wac/wit-bindgen-wrpc as the Windows fallback
# (varve ships no Windows binary). Its own bundled wasm_tools_toolchain is
# registered below, after the varve-backed ones, as that fallback.
wasm_toolchain = use_extension("//wasm:extensions.bzl", "wasm_toolchain")
wasm_toolchain.register(
name = "wasm_tools",
strategy = "download", # Download prebuilt binaries from GitHub releases
version = "1.246.2",
)
use_repo(wasm_toolchain, "wasm_tools_toolchains")
# WebAssembly Package Tools (wkg) toolchain — Windows fallback only (see
# above); linux/macos get wkg from varve (varve.configure(name =
# "varve_wasm_tools") below).
wkg = use_extension("//wasm:extensions.bzl", "wkg")
wkg.register(
name = "wkg",
strategy = "download",
version = "0.15.0",
)
use_repo(wkg, "wkg_toolchain")
# WASI SDK toolchain
wasi_sdk = use_extension("//wasm:extensions.bzl", "wasi_sdk")
wasi_sdk.register(
name = "wasi",
strategy = "download",
version = "32",
)
use_repo(wasi_sdk, "wasi_sdk")
# Register both WASI SDK and C++ toolchains
register_toolchains(
"@wasi_sdk//:wasi_sdk_toolchain",
"@wasi_sdk//:cc_toolchain",
)
# Register default C++ toolchains for host Rust binaries requiring C++ linking
register_toolchains("@bazel_tools//tools/cpp:all")
# TinyGo WASI Preview 2 toolchain
tinygo = use_extension("//wasm:extensions.bzl", "tinygo")
tinygo.register(
name = "tinygo",
tinygo_version = "0.40.1", # Must match version in checksums/tools/tinygo.json
)
use_repo(tinygo, "tinygo_toolchain")
register_toolchains("@tinygo_toolchain//:tinygo_toolchain_def")
# Wasmtime WebAssembly runtime (includes wizer as of v39.0.0)
# Note: Standalone wizer toolchain removed - use `wasmtime wizer` subcommand instead
wasmtime = use_extension("//wasm:extensions.bzl", "wasmtime")
wasmtime.register(
name = "wasmtime",
strategy = "download",
version = "45.0.1",
)
use_repo(wasmtime, "wasmtime_toolchain")
register_toolchains("@wasmtime_toolchain//:wasmtime_toolchain")
# C++ WebAssembly components with WASI SDK
cpp_component = use_extension("//wasm:extensions.bzl", "cpp_component")
cpp_component.register(
name = "cpp",
strategy = "download",
wasi_sdk_version = "32",
)
use_repo(cpp_component, "cpp_toolchain")
register_toolchains("@cpp_toolchain//:cpp_component_toolchain")
# Hermetic Node.js toolchain for JavaScript/TypeScript support
bazel_dep(name = "rules_nodejs", version = "6.5.0")
# Configure Node.js version and tools
node = use_extension("@rules_nodejs//nodejs:extensions.bzl", "node")
node.toolchain(node_version = "24.14.1")
use_repo(node, "nodejs_toolchains")
# JavaScript/TypeScript WebAssembly components with JCO
jco = use_extension("//wasm:extensions.bzl", "jco")
jco.register(
name = "jco",
node_version = "24.14.1",
version = "1.4.0",
)
use_repo(jco, "jco_toolchain")
# Register Node.js toolchains for JavaScript/TypeScript support
register_toolchains("@nodejs_toolchains//:all")
# Register jco toolchain for JavaScript/TypeScript components
register_toolchains("@jco_toolchain//:jco_toolchain")
# Python WebAssembly components with componentize-py
# NOTE: Not eagerly loaded - componentize-py uses a rolling canary release
# with no stable versions, causing checksum drift and build failures.
# Users who need Python components should opt in via language_extensions.bzl:
#
# python_wasm = use_extension("@rules_wasm_component//wasm:language_extensions.bzl", "python_wasm")
# python_wasm.configure()
# use_repo(python_wasm, "componentize_py_toolchain")
# register_toolchains("@componentize_py_toolchain//:componentize_py_toolchain")
# Binaryen (wasm-opt) toolchain for WebAssembly optimization
binaryen = use_extension("//wasm:extensions.bzl", "binaryen")
binaryen.register(
name = "binaryen",
version = "129",
)
use_repo(binaryen, "binaryen_toolchain")
register_toolchains("@binaryen_toolchain//:binaryen_toolchain")
# loom/meld/spar/synth/witness toolchains, sourced from varve (the
# PulseEngine toolchain layer manager) instead of this repo's own per-tool
# GitHub-release download + checksums/tools/*.json trust-on-first-use pin.
# One signed, counter-protected, dated layer (//:varve.toml) replaces five
# separately hand-maintained registry entries. See //varve/README.md for the
# trust model and //varve/toolchains:BUILD.bazel for the toolchain wiring.
#
# wsc (signing toolchain) stays on its existing path deliberately — a
# signing-path trust-source change needs its own explicit review, not a
# bundled one. rivet has no existing rules_wasm_component toolchain to
# migrate.
varve = use_extension("//varve:varve.bzl", "varve")
varve.configure(
pin = "//:varve.toml",
tools = [
"loom",
"meld",
"spar",
"synth",
"witness",
],
trust_root = "//:rolling.pub",
)
use_repo(varve, "varve_tools")
register_toolchains(
"//varve/toolchains:loom_toolchain",
"//varve/toolchains:meld_toolchain",
"//varve/toolchains:spar_toolchain",
"//varve/toolchains:synth_toolchain",
"//varve/toolchains:witness_toolchain",
)
# wasm-tools/wkg/wit-bindgen-wrpc, sourced from varve's pulseengine-wasm
# realm (ghcr.io/pulseengine/wasm-layers) instead of checksums/tools/*.json.
# A DIFFERENT realm than the one above: pulseengine-wasm carries
# bytecodealliance-origin tools, signed by a separate PulseEngine key
# (//:wasm-rolling.pub), not the pulseengine realm's key. See
# //:varve-wasm.toml's header for the proof-of-origin caveat — the two
# tools here besides wasm-tools carry no upstream provenance, unlike
# loom/meld/spar/synth/witness above.
#
# wac is DELIBERATELY NOT in this list, even though it's in the realm:
# toolchains/tool_versions.bzl pins wac at 0.9.0 specifically because
# "wac 0.9.0 does NOT support P3 async yet (issue #180)" — the realm's only
# published layer carries wac 0.11.0, which rejects the WASI P3 dual-compile
# composition (examples/rust_p3/p3_cli, actively developed) with "the async
# canonical option requires an async function type". Caught by this PR's own
# CI (Direct Integration Test), not assumed. wac stays on the old download
# path (still pinned at 0.9.0) until either P3 composition is updated for
# newer wac or the realm publishes a compatible version.
#
# wit-bindgen (plain), wasmtime, wasi-sdk, binaryen, and wrpc (non-wrpc-
# bindgen) are NOT in this realm and stay on their existing paths.
varve.configure(
name = "varve_wasm_tools",
pin = "//:varve-wasm.toml",
registry = "oci://ghcr.io/pulseengine/wasm-layers",
tools = [
"wasm-tools",
"wit-bindgen-wrpc",
"wkg",
],
trust_root = "//:wasm-rolling.pub",
)
use_repo(varve, "varve_wasm_tools")
# Order matters: toolchain resolution picks the first *matching*
# registration for the current exec platform. The linux/macos varve-backed
# toolchains must come before the unconstrained (exec_compatible_with = [])
# old-download fallbacks, or the fallback would win everywhere and the
# varve switch would be a no-op.
register_toolchains(
"//varve/toolchains:wasm_tools_toolchain_linux",
"//varve/toolchains:wasm_tools_toolchain_macos",
"@wasm_tools_toolchains//:wasm_tools_toolchain", # Windows fallback
"//varve/toolchains:wkg_toolchain_linux",
"//varve/toolchains:wkg_toolchain_macos",
"@wkg_toolchain//:wkg_toolchain_def", # Windows fallback
)
# File Operations Component toolchain for universal file handling
register_toolchains("//toolchains:file_ops_toolchain_target")
# External File Operations Component from bazel-file-ops-component
# Phase 2: External component with LOCAL AOT compilation
#
# We download the regular WASM component and compile AOT locally using our
# wasm_precompile rules. This guarantees compatibility with the user's
# Wasmtime version while maintaining 100x faster startup.
#
# WASM component downloads using centralized JSON registry
# All checksums verified from //checksums/tools/*.json
wasm_component_download = use_repo_rule("//toolchains:wasm_component_download.bzl", "wasm_component_download")
# File operations component (version in //checksums/tools/file-ops-component.json)
wasm_component_download(
name = "file_ops_component_external",
filename = "file_ops_component.wasm",
tool_name = "file-ops-component",
version = "0.2.0",
)
# WSC (WebAssembly Signature Component) for signing (version in //checksums/tools/wsc.json)
# Note: kept as wasmsign2_cli_wasm for backward compatibility with existing wrappers
wasm_component_download(
name = "wasmsign2_cli_wasm",
filename = "wasmsign2.wasm",
tool_name = "wsc",
version = "0.7.0",
)
# LOOM: consumed via the native loom toolchain, sourced from varve (above).
# The old @loom_wasm 0.3.0 component download was removed — loom v1.x is
# native-only and wasm_optimize now runs the native binary directly (#512).
# WASM Tools Component toolchain for universal wasm-tools operations
register_toolchains("//toolchains:wasm_tools_component_toolchain_local")
# Rust crates for tools
crate = use_extension("@rules_rust//crate_universe:extension.bzl", "crate")
crate.from_cargo(
name = "crates",
cargo_lockfile = "//tools/checksum_updater:Cargo.lock",
manifests = ["//tools/checksum_updater:Cargo.toml"],
supported_platform_triples = [
"wasm32-wasip2", # Enable WebAssembly WASI Preview 2 support
"wasm32-unknown-unknown",
"wasm32-wasip1",
"x86_64-unknown-linux-gnu",
"aarch64-unknown-linux-gnu", # BCR environment ARM64 Linux
"aarch64-apple-darwin",
"x86_64-pc-windows-msvc",
],
)
crate.from_cargo(
name = "wasmsign2_crates",
manifests = ["@wasmsign2_src//:Cargo.toml"],
supported_platform_triples = [
"x86_64-unknown-linux-gnu",
"aarch64-unknown-linux-gnu", # BCR environment ARM64 Linux
"aarch64-apple-darwin",
"x86_64-pc-windows-msvc",
],
)
crate.from_cargo(
name = "ssh_keygen_crates",
cargo_lockfile = "//tools/ssh_keygen:Cargo.lock",
manifests = ["//tools/ssh_keygen:Cargo.toml"],
supported_platform_triples = [
"wasm32-wasip2", # Enable WebAssembly WASI Preview 2 support
"wasm32-wasip1",
"wasm32-unknown-unknown",
"x86_64-unknown-linux-gnu",
"aarch64-unknown-linux-gnu",
"x86_64-apple-darwin",
"aarch64-apple-darwin",
"x86_64-pc-windows-msvc",
],
)
crate.from_cargo(
name = "wasm_embed_aot_crates",
cargo_lockfile = "//tools/wasm_embed_aot:Cargo.lock",
manifests = ["//tools/wasm_embed_aot:Cargo.toml"],
supported_platform_triples = [
"x86_64-unknown-linux-gnu",
"aarch64-unknown-linux-gnu",
"x86_64-apple-darwin",
"aarch64-apple-darwin",
"x86_64-pc-windows-msvc",
],
)
# Note: wit-bindgen-rt crate is available from checksum_updater/Cargo.toml (version 0.39.0)
# It provides the proper runtime support for CLI-generated bindings:
# - export! macro for component exports
# - wit_bindgen::rt module with correct allocator integration
# This replaces the previously embedded runtime stubs
use_repo(crate, "crates", "ssh_keygen_crates", "wasm_embed_aot_crates", "wasmsign2_crates")
# Modernized WASM tool repositories using git_repository + rules_rust
wasm_tool_repos = use_extension("//toolchains:extensions.bzl", "wasm_tool_repositories")
use_repo(
wasm_tool_repos,
"wac_src",
"wasm_tools_src",
"wasmsign2_src",
"wit_bindgen_src",
"wrpc_src",
)